
Senior Microsoft 365 Engineer
Posted 11 hours ago

Posted 11 hours ago
This is a fully remote position, open to applicants in United States.
β’ Take charge of the Microsoft 365 platform at WellStreet.
β’ Develop a sensitivity label taxonomy and Data Loss Prevention (DLP) policies across Exchange, SharePoint, and Teams.
β’ Design and oversee Entra ID management, encompassing Conditional Access, hybrid identity, privileged access, password protection, Self-Service Password Reset (SSPR), and access reviews.
β’ Set up and maintain Intune across Windows, macOS, iOS, and Android, including compliance and configuration profiles, security baselines, Autopilot, update rings, and app packaging.
β’ Oversee the configuration of Exchange Online, Teams, and SharePoint tenant, including mail flow and transport rules.
β’ Configure Purview DLP, sensitivity labeling, retention, auditing, eDiscovery, and HIPAA/HITRUST control mapping.
β’ Implement and manage Single Sign-On (SSO) and System for Cross-domain Identity Management (SCIM) across enterprise applications.
β’ Manage Defender endpoint detection and response, Defender for Office 365 anti-phishing and threat investigation, and unified M365 alerting.
β’ Assess Common Vulnerabilities and Exposures (CVEs) from SecOps, track remediation, and generate weekly reports.
β’ Maintain a precise application catalog, efficient runbooks, vendor SLAs, and Business Associate Agreements (BAAs).
β’ Build version-controlled, API-driven M365 management in an Azure DevOps repository utilizing Microsoft Graph and PowerShell, employing app-only authentication and Key Vault.
β’ Utilize Python or declarative tools where applicable.
β’ Review AI-assisted tasks prior to their impact on tenants holding Protected Health Information (PHI).
β’ A minimum of five years in M365, identity, or security engineering.
β’ In-depth knowledge of Entra ID and Intune at the tenant level.
β’ Hands-on experience configuring Purview, including DLP policies, labeling, retention, and eDiscovery.
β’ Proficiency in Microsoft Graph and PowerShell; automation is a priority, with experience in API development.
β’ Knowledge of Python is advantageous.
β’ Familiarity with version control practices, including typical use of branches and pull requests.
β’ Experience with HIPAA, HITRUST, SOC 2, or PCI, with the ability to articulate controls.
β’ Daily utilization of AI and sound judgment regarding what needs review before affecting tenants holding PHI.
β’ Familiarity with Terraform, Bicep, or Azure DevOps pipelines is preferred.
β’ Exposure to declarative M365 management, including Microsoft365DSC, a Terraform M365 provider, or Graph Tenant Configuration Management APIs is a plus.
β’ Background in Healthcare IT is beneficial.
β’ Experience managing a vulnerability or patch compliance program is advantageous.
β’ Familiarity with FreshService or comparable IT Service Management (ITSM) tools is preferred.
β’ ITIL v4 certification is a plus.
β’ Certifications such as SC-200, SC-300, SC-400, MS-102, or MD-102 are desirable.
β’ Full-time remote work opportunity.
β’ Genuine platform ownership with the freedom and responsibility to build an engineering practice.
β’ Chance to establish standards for version control, review, and automation.
β’ Opportunity to become a clear leader as more engineers join the team.
β’ Utilize AI within engineering, administration, and documentation efforts.
University Hospitals Urgent Care
Prisma Health Urgent Care
Canadian Solar Inc.
Canadian Solar Inc.
Get handpicked remote jobs straight to your inbox weekly.